AI, Customer Data and Privacy: What Small Businesses Need to Get Right
Most businesses discover their AI data privacy position the same way: a customer asks where their information is stored, and nobody in the office knows. The tool was signed up for on a card, connected to the calendar and the enquiry inbox, and the settings page has not been opened since.
That gap is worth closing, and closing it is mostly administrative rather than technical. Getting AI data privacy right in a small business comes down to knowing where the data physically sits, deciding how long it stays there, and being able to say who at the vendor can read it. None of that requires a lawyer or an IT department, though it does require someone to spend an hour on the settings page and another hour on email.
This is general practical guidance rather than legal advice. For how New Zealand's information privacy principles apply to AI tools specifically, the Privacy Act guide covers the legal side, and the Office of the Privacy Commissioner publishes plain-language material worth reading directly.
Know what your AI system can actually see#
Start with an inventory, because most businesses are surprised by it. Every AI tool you use holds some slice of customer information, and the slice is usually wider than you assumed at signup.
An AI phone or chat agent holds the conversation itself, which typically contains a name, a phone number, an address and a description of somebody's problem. If it books jobs, it also touches your calendar. If it is connected to your CRM, it may be able to read the entire customer history rather than just the record in front of it.
That last point is the one worth acting on first. Many integrations request broad access because broad access is easier to build, and the agent then has permission to read records it will never need. Ask whoever set it up to narrow the connection to the fields the agent actually uses. An agent answering enquiries needs services, prices and availability rather than five years of invoice history.
The related question is what you feed it deliberately. When you build the knowledge base, it is easy to paste in a document that contains customer names or pricing you would not want quoted publicly. The piece on what to feed an AI agent covers what belongs in there, and the rule is that anything in the knowledge base can end up in an answer.
The four settings that do most of the work#
Training opt-out#
The question is whether your conversations get used to improve the vendor's models. Business and enterprise tiers from the major providers generally exclude customer data from training. Free and consumer tiers often do not, and plenty of small businesses are running an AI tool on a consumer plan without realising the distinction exists.
Find the setting, turn training off, and then ask the vendor to confirm the position by email. The email matters because settings pages change and you want a dated record of what you were told.
Data residency#
Where the data physically sits. Most AI vendors run in the United States or in Australia, and a smaller number offer a choice. For most New Zealand service businesses this is a disclosure question rather than a blocker, since offshore storage is common and manageable. It does become a real constraint if you hold health information or work under a professional obligation that specifies handling, which is why practices in accounting and advisory tend to ask about it first.
Whatever the answer is, write it into your privacy statement in a sentence a customer could understand.
Retention window#
How long conversations are kept before deletion. Vendors often default to a long window, sometimes indefinite, because storage is cheap and it helps their debugging.
Decide what you actually need. If you use transcripts to improve the agent and to settle the occasional dispute about what was promised, ninety days probably covers it. Shorten the window to that and the amount of data at risk in any future incident drops accordingly. This is the single highest-value setting change most businesses can make, and almost nobody makes it.
Who can read the conversations#
Vendors usually have support staff who can access customer data for troubleshooting. That is normal and it should be bounded. Ask whether access is logged, whether it requires your approval, and whether staff access is restricted to specific support tickets.
On your own side, apply the same thinking. If four people have logins to the AI platform and only one of them needs to read transcripts, remove the other three. Most small business data incidents are ordinary rather than dramatic, involving a shared login or an account belonging to someone who left months ago.
Keep the genuinely sensitive material out of the conversation#
The cleanest way to protect data is to not collect it in the first place. An AI agent taking enquiries has no reason to handle a credit card number, a bank account or a copy of somebody's identification, and you should configure it to refuse when a customer offers.
Set an explicit instruction that the agent never asks for payment details and redirects the customer to your normal payment process if they try to provide them. Do the same for anything a customer might volunteer about their health, unless you are a clinic and have deliberately designed for it.
This matters because customers overshare. Someone describing why they need a locksmith at eleven at night will tell an AI agent things they would not put in a form. Your transcripts will contain more personal detail than you expected, which is another argument for a short retention window.
The vendor questions worth asking before you sign#
Copy these into an email and send them before you commit. A vendor who answers all six clearly and quickly is telling you something useful about how they operate.
- Where is our data physically stored, and can we choose the region?
- Is our conversation data used to train your models, or any third party's models, and how do we opt out?
- What is the default retention period, and can we shorten it?
- Which of your staff can read our conversations, under what circumstances, and is that access logged?
- If we cancel, what happens to our data, how long until it is deleted, and can we export it first?
- Which sub-processors do you use, and where are they based?
The last one catches something people miss. Your vendor may be a New Zealand or Australian company while the model behind their product belongs to someone else entirely, so the relevant privacy terms are theirs as much as your vendor's.
Add a seventh question if you are being quoted for a custom system rather than a subscription, which is who holds the credentials and the hosting account. The build versus buy comparison goes into why that ownership question tends to surface at the worst possible moment.
Tell customers, in one sentence#
You do not need a policy rewrite. You need a line on your privacy page and, ideally, a line in the agent's opening message saying that they are talking to an AI assistant and that the conversation is recorded to handle their enquiry.
Being upfront about the AI costs you almost nothing. People are generally fine with it when the thing is useful and answers quickly, and they are considerably less fine when they work it out themselves halfway through.
What to do this week#
Open the settings page of every AI tool you pay for and check two things: whether training on your data is off, and what the retention window is set to. Change what needs changing and note the date you did it.
Then send the six questions to any vendor you are currently evaluating, before the demo rather than after. Their answers will separate the serious operators from the resellers faster than any feature comparison. For where this fits alongside the rest of an AI programme, the overview of AI solutions for small business sets out the order to tackle things in.
Common questions
Do AI tools train on my customer conversations?
Some do by default and some never do. Business plans from major providers generally exclude customer data from training, while free and consumer tiers often do not. The setting is usually available but rarely on by default, so check it explicitly and ask the vendor to confirm the position in writing.
What should I ask an AI vendor about data privacy?
Ask where the data is physically stored, whether it is used for model training, how long conversations are retained and whether you can shorten that, which of their staff can read conversations, and what happens to your data if you cancel. Vague answers to any of these are a reason to look elsewhere.
Is it safe to let an AI agent handle customer enquiries?
It can be, provided you limit what the agent can see and do. Give it the information needed to answer enquiries rather than access to your full customer database, keep payment details and identity documents out of the conversation entirely, and make sure a human reviews anything sensitive.